Одно посещение вредоносной страницы могло скомпрометировать Tor Browser
Researchers from Nebula Security have revealed details about the vulnerability CVE-2026-10702 in Firefox's JIT compiler, which could allow arbitrary code execution within the browser process. This flaw also impacted Tor Browser when running on compromised versions of Firefox. Attackers could exploit this issue simply by visiting a malicious webpage—no user interaction was required. Mozilla addressed the problem in Firefox 151.0.3, and all stable releases from Firefox 147 up to 151.0.2 are considered vulnerable. Although the Tor Browser’s exact affected versions remain unspecified, any release built on these Firefox versions is potentially at risk. Researchers demonstrated that CVE-2026-10702 served as part of a multi-stage attack chain targeting Android devices, leveraging another vulnerability known as GhostLock (CVE-2026-43499) to gain full system control.